TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Toward a Passwordless Future

29 点作者 freddyym3 个月前

16 条评论

grammarxcore3 个月前
The big thing missing from the article is how a device that contains many passkeys is any different from a password manager that enforces security settings. I don’t worry about passwords my password manager generates getting compromised because I use at least 24 random characters (assuming my password manager is using a cryptographically secure PRNG that guarantees some level of randomness, giving us more than 128 bits). Assuming I use that to manage the password to my email, I really only have to worry about my password manager key being compromised. I only used my password manager on trusted devices so I really only have to worry about my trusted devices being compromised.<p>If I use passkeys, I have to worry about my trusted devices being compromised. According to the article, “as long as you can remember your phone password, you can log in to your accounts.” That sounds like my password manager. The other benefits also sound like a combination of my password manager and privacy focus. I’m not saying this is bad; I just don’t see how it’s different from a security-conscious status quo.
评论 #43305558 未加载
评论 #43305531 未加载
carlhjerpe3 个月前
I really don&#x27;t want to use Passkeys until they can be stored in my password manager of choice on Linux, Android and Windows.
评论 #43305383 未加载
评论 #43305589 未加载
评论 #43305435 未加载
评论 #43306077 未加载
评论 #43305429 未加载
kemotep3 个月前
I wish first and foremost that all my accounts could support passkeys&#x2F;passwordless sign ins instead of only like 12&#x2F;60.<p>My second wish would be that passkeys should be as easy to work with as ssh keys. Somehow, they tend to be more complicated. Asking you if you want to use your phone or security key (when you have neither, you are using a password manager) and often failing to immediately detect your preferred method of storing them, defaulting to Google, Microsoft, or Apple&#x27;s solutions.
0xbadcafebee3 个月前
Passkeys are not a panacea. They&#x27;re an amalgam of multiple standards that half the time aren&#x27;t implemented right or not fully supported. It&#x27;s the industry&#x27;s attempt to design-by-committee a one-size-fits all solution to many, many different problems. News flash: one-size-fits-all fits nobody well.<p>Passwords are a perfectly fine single factor. Add more factors to get more security, in specific use cases where they make sense. Passkeys don&#x27;t fill the use case that a single-factor like passwords do.<p>Password Managers are also perfectly fine when combined with multiple factors and attack mitigations (and are certainly no worse than Passkeys we have now, key access managed by a central piece of software&#x2F;key control&#x2F;authorization). They solve many different use cases without breaking others. They&#x27;re customizable, and not overly-dependent on standards. They are a loosely-coupled interface. They can be synchronized for multiple device&#x2F;site access. They can be upgraded to support an infinite amount of security mechanisms. They can be changed in backwards-compatible ways, and they don&#x27;t force one-size-fits-all on anybody. They even support Passkeys without forcing you to use them (though of course lots of Passkey software ignores the fact that you might have a password manager, and forces you to use the browser&#x27;s Passkey store or nothing).<p>You want to uniquely identify a device? Fingerprint it on login. Having a separate passkey per device isn&#x27;t any better, because if the attacker can get the device fingerprint, they can also probably get the passkey, because they have access to the device. And password reset still has to be a thing, because we all lose devices, backup codes, etc, so it&#x27;s not like there isn&#x27;t an easier attack anyway.<p>How is the passkey that much better than client-side certificates from 15 years ago? That was abandoned because of all the problems around key management; and now you want to bring back key management?!<p>Please stop trying to solve a problem by creating more problems. This is all about use cases. Just let users, and companies, decide what use cases they&#x27;ll support. Don&#x27;t force everyone to use a crap solution just because it makes big corporations happy.
sedatk3 个月前
The article praises passkeys for not even needing email for login, but omits to mention recovery flow. How do you recover your account if you lost your access to the passkey provider, and you didn&#x27;t provide an email address?<p>So, I think &quot;not even needing email&quot; is unlikely for foreseeable future, unless we find other ways to authenticate people reliably.
评论 #43306345 未加载
zabzonk3 个月前
A password, and extra secret information on things like my bank account have always worked well for me. I simply cannot stand 2FA using a smartphone. Why? Because I don&#x27;t have or want one. Luckily, my bank allows use of a landline for 2FA, which works perfectly, but I dread the day they stop supporting it.<p>Also, the whole bloody thing with passwords is noxious. I don&#x27;t want to login to your site, I just want to read some stuff.
xet73 个月前
I wish SQRL would become more popular.<p><a href="https:&#x2F;&#x2F;www.grc.com&#x2F;sqrl&#x2F;sqrl.htm" rel="nofollow">https:&#x2F;&#x2F;www.grc.com&#x2F;sqrl&#x2F;sqrl.htm</a>
评论 #43305743 未加载
ajsnigrutin3 个月前
So... what happens with passkeys if you lose&#x2F;break&#x2F;someone_steals your phone?<p>I&#x27;m talking about normal users, without backups.
评论 #43305532 未加载
评论 #43305216 未加载
评论 #43305238 未加载
评论 #43305376 未加载
评论 #43305677 未加载
评论 #43305440 未加载
ziggure3 个月前
The problem with passkeys is that they couple a security credential to a device containing lots of personal information. I don&#x27;t take my phone into certain countries where I sometimes travel, but I do bring my yubikey. I get the security benefits without the exposure of everything that&#x27;s on my phone.
brickfaced3 个月前
So it&#x27;s effectively SSH keys, but for regular app&#x2F;site logins with a nicer UI.
评论 #43305575 未加载
derbOac3 个月前
<a href="https:&#x2F;&#x2F;shkspr.mobi&#x2F;blog&#x2F;2022&#x2F;06&#x2F;ive-locked-myself-out-of-my-digital-life&#x2F;" rel="nofollow">https:&#x2F;&#x2F;shkspr.mobi&#x2F;blog&#x2F;2022&#x2F;06&#x2F;ive-locked-myself-out-of-my...</a>
immibis3 个月前
I&#x27;ve only heard bad things about privacyguides.org.<p><a href="https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;PrivacyGuides&#x2F;comments&#x2F;thnjjf&#x2F;privacyguidesorg_considered_harmful&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;PrivacyGuides&#x2F;comments&#x2F;thnjjf&#x2F;priva...</a>
评论 #43306019 未加载
CatWChainsaw3 个月前
Still a no from me. Right now passkeys are just a way for services to exert more control over users. I don&#x27;t see that changing for decades at minimum.
评论 #43305615 未加载
rijenkii3 个月前
Article talks how password managers are bad because they are a single point of failure, and then suggests syncing passkeys between devices using... password managers.<p>What? Who wrote this?
callc3 个月前
I am largely unconvinced of the downsides of passwords presented in the article. Especially the historical angle. Old != bad. In fact, it is a testament to the fact the the password system is simple enough to be done analog, easily understood without any training.<p>My question to the people here is are passkeys actually the future? Or are they an over-hyped over-engineered being forced on everyone? I say this as someone not knowing much of passkeys. And I&#x27;m not a fan of the &quot;holier than thou&quot; feeling from people proselytizing passkeys. Take the public&#x27;s &#x2F; user&#x27;s doubts seriously. You wouldn&#x27;t break into someone&#x27;s home and force them to get a different lock mechanism for their safe, or front door.<p>---<p>Counter-points to &quot;password bad&quot;<p>&gt; Password Overload<p>Use a password manager.<p>&gt; Email Requirement<p>Passwords don&#x27;t require email. Email is a used as user ID commonly. You can also use other mechanisms such as &quot;store this long key in your records and if you forget your U+PW then use it for recovery&quot;.<p>&gt; Single Point of Failure ... email acts as a one-stop shop for attackers looking to hack your accounts, either by getting into your email account itself or by sending you convincing password reset emails that send you to a phishing page ...<p>I agree. Solely having &quot;what you know&quot; info makes phishing possible.<p>&gt; Service Provider Negligence<p>A weak argument that could be applied anywhere to &quot;but I don&#x27;t trust them to do the right thing&quot;. All we need is good U+PW auth libraries and clear education like <a href="https:&#x2F;&#x2F;thecopenhagenbook.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;thecopenhagenbook.com&#x2F;</a>. Give actually big fines for companies that have breaches, then magically security will get better.<p>&gt; Human Error ... passwords rely on randomness to be secure, but they also rely on humans to generate them... Humans are very bad at generating random numbers<p>Use a password manager. This article reeks of a wannabe expert tone with the certainty, finality, and generality (I can speak confidently yet have an out because I used the word &quot;most&quot; or &quot;possibly&quot;!) of its claims.<p>&gt; Imagine if every time you connected to a website with HTTPS, you had to come up with your own encryption key. Would that be a secure system?<p>I can&#x27;t take the author seriously with these arguments. Put your big boy&#x2F;girl pants on and use your brain, stop using hypothetical straw-mans to easily knock down.
sdsd3 个月前
Cool but this (ie pw&#x27;s) isn&#x27;t how to steal accounts anyway. Eg when wanting to use AI models for free, just spin up a github dork, no passwords required. Eg, &#x2F;&quot;Authorization: Bearer xai-.+&quot;&#x2F; gives free Grok API key. Try a few until one works and viola.<p>Plug in the API key and now my app is grokified. or if I&#x27;m really wanting that classic experience, ask the free version of grok to spin up a react interface that uses the api key, and then plug in. Wow.<p>Or if really desperate, make a quick fake NPM package, ask rando dev to npm install it bc its not working with their FOSS project or whatever, say nvm it works now! And it exfiltrates the API key someone wants.<p>I&#x27;d never do any of this bc I&#x27;m a latter day saint, but maybe I would if I needed a key in a jiffy who even knows